Debian Linux vulnerabilities
9,954 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4167MEDIUM4296LOW358
Vulnerabilities
Page 320 of 498
CVE-2020-6460P4MEDIUMCVSS 6.5v9.0v10.02020-05-21
CVE-2020-6460 [MEDIUM] CVE-2020-6460: Insufficient data validation in URL formatting in Google Chrome prior to 81.0.4044.122 allowed a rem
Insufficient data validation in URL formatting in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to perform domain spoofing via a crafted domain name.
nvd
CVE-2021-38022P4MEDIUMCVSS 6.5v10.0v11.02021-12-23
CVE-2021-38022 [MEDIUM] CVE-2021-38022: Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a r
Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-24370P4MEDIUMCVSS 5.3v9.02020-08-17
CVE-2020-24370 [MEDIUM] CWE-191 CVE-2020-24370: ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
nvd
CVE-2023-23589P4MEDIUMCVSS 6.5v10.0v11.02023-01-14
CVE-2023-23589 [MEDIUM] CWE-693 CVE-2023-23589: The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol ca
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.
nvd
CVE-2021-38019P4MEDIUMCVSS 6.5v10.0v11.02021-12-23
CVE-2021-38019 [MEDIUM] CWE-670 CVE-2021-38019: Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote atta
Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-38009P4MEDIUMCVSS 6.5v10.0v11.02021-12-23
CVE-2021-38009 [MEDIUM] CWE-203 CVE-2021-38009: Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attack
Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-43750P4MEDIUMCVSS 6.7v10.02022-10-26
CVE-2022-43750 [MEDIUM] CWE-787 CVE-2022-43750: drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a
drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory.
nvd
CVE-2018-5131P4MEDIUMCVSS 5.9v7.0v8.0+1 more2018-06-11
CVE-2018-5131 [MEDIUM] CWE-200 CVE-2018-5131: Under certain circumstances the "fetch()" API can return transient local copies of resources that we
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored, locally cached data of a website being accessible to users if they share a common profile while brows
nvd
CVE-2021-21164P4MEDIUMCVSS 6.5v10.02021-03-09
CVE-2021-21164 [MEDIUM] CWE-346 CVE-2021-21164: Insufficient data validation in Chrome on iOS in Google Chrome on iOS prior to 89.0.4389.72 allowed
Insufficient data validation in Chrome on iOS in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-37989P4MEDIUMCVSS 6.5v10.0v11.02021-11-02
CVE-2021-37989 [MEDIUM] CVE-2021-37989: Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 allowed a remote attack
Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to abuse content security policy via a crafted HTML page.
nvd
CVE-2021-37994P4MEDIUMCVSS 6.5v10.0v11.02021-11-02
CVE-2021-37994 [MEDIUM] CVE-2021-37994: Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remo
Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2023-4874P4MEDIUMCVSS 6.5v10.0v11.0+1 more2023-09-09
CVE-2023-4874 [MEDIUM] CWE-475 CVE-2023-4874: Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12
Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12
nvd
CVE-2022-20369P4MEDIUMCVSS 6.7v10.02022-08-11
CVE-2022-20369 [MEDIUM] CWE-787 CVE-2022-20369: In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper inpu
In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-223375145References: Upstream kernel
nvd
CVE-2015-8629P4MEDIUMCVSS 5.3v7.0v8.02016-02-13
CVE-2015-8629 [MEDIUM] CWE-125 CVE-2015-8629: The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) befo
The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted string.
nvd
CVE-2020-15954P4MEDIUMCVSS 6.5v9.02020-07-27
CVE-2020-15954 [MEDIUM] CWE-319 CVE-2020-15954: KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI in
KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.
nvd
CVE-2020-14093P4MEDIUMCVSS 5.9v8.0v9.0+1 more2020-06-15
CVE-2020-14093 [MEDIUM] CWE-319 CVE-2020-14093: Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
nvd
CVE-2020-16117P4MEDIUMCVSS 5.9v9.02020-07-29
CVE-2020-16117 [MEDIUM] CWE-476 CVE-2020-16117: In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a N
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
nvd
CVE-2023-5197P4MEDIUMCVSS 6.6v10.02023-09-27
CVE-2023-5197 [MEDIUM] CWE-416 CVE-2023-5197: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
Addition and removal of rules from chain bindings within the same transaction causes leads to use-after-free.
We recommend upgrading past commit f15f29fd4779be8a418b66e9d52979bb6d6c2325.
nvd
CVE-2021-32686P4MEDIUMCVSS 5.9v9.0v11.02021-07-23
CVE-2021-32686 [MEDIUM] CWE-362 CVE-2021-32686: PJSIP is a free and open source multimedia communication library written in C language implementing
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP before version 2.11.1, there are a couple of issues found in the SSL socket. First, a race condition between callback and destroy, due to the accepted socket having no group
nvd
CVE-2019-19709P4MEDIUMCVSS 6.1v9.0v10.02019-12-11
CVE-2019-19709 [MEDIUM] CWE-601 CVE-2019-19709: MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by star
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.
nvd